CVE-2023-4966 is a critical, unauthenticated information-disclosure flaw in Citrix NetScaler ADC and NetScaler Gateway, with a CVSS score of 9.4. The vulnerability, known as Citrix Bleed, affects OpenID Connect discovery endpoints: an attacker can send an oversized HTTP Host header to trigger an out-of-bounds memory disclosure.
The flaw stems from improper handling of snprintf return values while constructing a JSON response in a 0x20000-byte static buffer. Exposed process memory can contain valid NSC_AAAC session cookies, enabling attackers to replay stolen tokens and impersonate authenticated users in affected deployments. Citrix issued security guidance and remediated the issue by preventing responses when the generated content exceeds the allocated buffer.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers demonstrated that an oversized HTTP Host header could trigger an out-of-bounds memory disclosure on NetScaler 13.1-48.47. The disclosed memory included valid NSC_AAAC session cookies that could be reused to identify an authenticated user's session in affected configurations.
Citrix addressed the flaw in NetScaler version 13.1-49.15 by checking that snprintf's generated response length is smaller than the allocated 0x20000-byte buffer before sending the response.
Citrix disclosed CVE-2023-4966 as a critical, unauthenticated sensitive-information disclosure flaw in NetScaler ADC and NetScaler Gateway, with a CVSS score of 9.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.